ESET researchers uncovered dozens of fake WhatsApp and Telegram websites distributing trojanized Android and Windows installers aimed largely at Chinese-speaking users trying to access blocked messaging services outside official app stores. The malicious Android apps included the first observed clipper malware embedded in instant messaging clients, replacing cryptocurrency wallet addresses in chats so funds would be redirected to attacker-controlled accounts. Some samples also used OCR to scan screenshots and photos for wallet recovery phrases, while other variants exfiltrated messages, Telegram data, device details, and files.
On Windows, the campaign delivered both Telegram clippers and bundled remote access trojans (RATs) that enabled keylogging, clipboard theft, screen capture, and file operations. Victims were lured through Google Ads, fraudulent YouTube channels, and counterfeit download pages impersonating legitimate messaging services. ESET said the operation reflects a broader cryptocurrency-theft ecosystem built around fake messaging apps and reported the malicious ads and channels to Google, which removed them.

Track how attackers are adapting to this technology.
4 events from the most recent confirmed update back to the earliest known activity.
After ESET reported the campaign's malicious Google Ads and fraudulent YouTube channels to Google, the company removed them. This action disrupted part of the distribution infrastructure used to lure victims to counterfeit download sites.
ESET found Windows-based fake Telegram and WhatsApp installers containing clippers that alter cryptocurrency wallet addresses in messages as well as bundled remote access trojans. The RAT functionality included keylogging, clipboard theft, screen capture, and file operations.
ESET reported Android malware embedded in fake messaging apps, including the first observed clippers in instant messaging apps that replace cryptocurrency wallet addresses in chats. Some samples also used OCR to scan screenshots and photos for wallet recovery phrases, and ESET grouped the threats into four Android clusters with varying theft capabilities.
ESET researchers identified dozens of fake Telegram and WhatsApp websites distributing trojanized Android and Windows apps, primarily targeting Chinese-speaking users seeking blocked services outside official channels. The campaign used Google Ads, fraudulent YouTube channels, and counterfeit download sites to lure victims.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 75 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
3 references tracked. Mallory keeps watching after this page renders.
welivesecurity.com
Open sourceattack.mitre.org
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.